Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-99jg-2fvv-2jfq

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

A business logic issue in the MStore API WordPress plugin, versions before 3.2.0, had an authentication bypass with Sign In With Apple allowing unauthenticated users to recover an authentication cookie with only an email address.

A business logic issue in the MStore API WordPress plugin, versions before 3.2.0, had an authentication bypass with Sign In With Apple allowing unauthenticated users to recover an authentication cookie with only an email address.

EPSS

Процентиль: 90%
0.05628
Низкий

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 9.8
nvd
почти 5 лет назад

A business logic issue in the MStore API WordPress plugin, versions before 3.2.0, had an authentication bypass with Sign In With Apple allowing unauthenticated users to recover an authentication cookie with only an email address.

EPSS

Процентиль: 90%
0.05628
Низкий

Дефекты

CWE-287